Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
content management system vulnerabilities and exploits
(subscribe to this query)
668
VMScore
CVE-2005-2489
Web Content Management News System allows remote malicious users to create arbitrary accounts and gain privileges via a direct request to Admin/Users/AddModifyInput.php.
Web Content Management Web Content Management News System
440
VMScore
CVE-2005-2488
Cross-site scripting (XSS) vulnerability in Web Content Management News System allows remote malicious users to inject arbitrary web script or HTML via (1) the strRootpath parameter to validsession.php or (2) the strTable parameter to Admin/News/List.php.
Web Content Management Web Content Management News System
2 EDB exploits
312
VMScore
CVE-2020-36498
Macrob7 Macs Framework Content Management System - 1.14f contains a cross-site scripting (XSS) vulnerability in the account reset function, which allows malicious users to execute arbitrary web scripts or HTML via a crafted payload in the e-mail input field.
Macrob7 Macs Framework Content Management System Project Macrob7 Macs Framework Content Management System 1.14f
685
VMScore
CVE-2006-7079
Variable extraction vulnerability in include/common.php in exV2 2.0.4.3 and previous versions allows remote malicious users to overwrite arbitrary program variables and conduct directory traversal attacks to execute arbitrary code by modifying the $xoopsOption['pagetype'...
Exv2 Content Management System
1 EDB exploit
435
VMScore
CVE-2006-7080
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and previous versions allows remote malicious users to delete arbitrary files via ".." sequences in the old_avatar parameter.
Exv2 Content Management System
1 EDB exploit
383
VMScore
CVE-2007-4365
Cross-site scripting (XSS) vulnerability in eXV2 CMS 2.0.5 and previous versions allows remote malicious users to inject arbitrary web script or HTML via a set_lang cookie to an unspecified component. NOTE: this may overlap CVE-2007-1965.
Exv2 Content Management System
NA
CVE-2023-48985
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote malicious user to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the login.php component.
Cusg Content Management System
755
VMScore
CVE-2006-5030
SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and previous versions allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.
Exv2 Content Management System
1 EDB exploit
NA
CVE-2023-48986
Cross Site Scripting (XSS) vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote malicious user to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the users.php component.
Cusg Content Management System
NA
CVE-2023-48987
Blind SQL Injection vulnerability in CU Solutions Group (CUSG) Content Management System (CMS) before v.7.75 allows a remote malicious user to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted script to the pages.php component.
Cusg Content Management System
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
blind SQL injection
SSRF
buffer overflow
CVE-2023-28952
CVE-2023-41822
CVE-2024-27956
CVE-2023-7028
CVE-2024-34447
CVE-2024-34460
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »